ZyXel ZyWall 10 internet security gateway and router reviewed

Menu: Main Functions   Internet Sharing   Computer Networking   Shopping   About Us  
More About Broadband Routers 
  | Overview & Guide | | Reviews | | Help |  
Networking
Review Indexes
Featured Reviews
-
Broadband Routers
-
Wireless Ethernet
-
HPNA, Phoneline Networking
-
Software
-
Books
-
Other Reviews
ZyWall 10 Internet Security Gateway  link
from ZyXEL link
Review Type: Hands On
Reviewer: Chris Kaminski
Date: Feb 13, 2001
www.homenethelp.comThe ZyWall 10 is one of the first in a series of Cable/DSL routers / firewalls that we will be seeing this year. As security awareness on the internet builds, consumer are demanding better security for their home networks – security that goes beyond simple NAT addressing security. The ZyWall 10 appears to be in a good spot to fill this need.
Security Note
ZyNOS ZyWall Network Operating System passed the ICSA.NET firewall certification - link  
ZyXEL has been in the firewall and security business for quite some time. They built a networking operating system, called ZyNOS, that has been the core of their previous firewall products. ZyXEL has built this product, the ZyWall10 around their newest release of ZyNOS, ver 3.20. This new version features a web interface and a setup wizard making it perfect for home network users wanting more security without the huge learning curve real firewalls have demanded in the past.
What the ZyWall 10 can do for you
Connection Sharing
Like other broadband routers, the ZyWall 10 implements NAT. This allows multiple computers on your private LAN to access the internet through a single IP address. The ZyWALL 10 also implements other kinds of NAT for some real unique configurations.
Firewall
The ZyWall 10 is “pre-configured to automatically detect and thwart Denial of Service (DoS) attacks such as Ping of Death, SYN Flood, LAND attack, IP Spoofing, etc. It also uses stateful packet inspection to determine if an inbound connection is allowed through the firewall to the private LAN”. This keeps hackers out of your system, AND it keeps them from denying you access to the internet with DoS attacks. Additionally, the ZyWall 10 actually lets you configure your TCP and UDP timeouts.
Attack Alert Logs
If someone IS attacking your network, the ZyWall 10 can be configure to let you know about it. Not only will it e-mail you an attack log on a schedule, you can have it e-mail you immediately on certain attack occurrences.
Blocking and Content Filtering
Using the web interface, the ZyWall 10 can be configured to deny access to certain domains. It can also block cookies, ActiveX objects, and JAVA!
Installing the ZyWall 10
Since the ZyWall 10 does not include a switch for your lan, you will need an external one. Just string a Cat5 between the uplink cable of your switch and the ZyWall lan port. If your hub/switch does not have an uplink port, the ZyWall has a handy switch on the back to turn it’s LAN port into an uplink port.
The ZyWall 10 defaults to an IP address of 192.168.1.1 subnet 255.255.255.0. You will have to set one of your computers to an IP address in that range – like 192.168.1.2 subnet 255.255.255.0. Once that is done, simply open your web browser and point to http://192.168.1.1 . The ZyWall will ask you for a user ID and password (admin,1234) and will then display your main menu. I would suggest running through the ‘Wizard Setup’.
Next, click the LAN button at the left of the screen. The wizard only asked for your primary DNS server, so you will have to type the secondary one in on this screen. Also make sure that your DHCP server is enabled.
ZyWall 10 Security Test
We ran the ZyWall 10 through a couple of intense secuity tests on the internet.  It passed them both with flying colors.  A perfect score was obtained from HackerWhacker and Shield Probe at DSL Reports reported a -1 (0 is perfect).  Click HERE to see the Shield Probe results.
A couple things that could use some help
  • The firewall e-mail alert system does not allow e-mail to be sent through a secure e-mail server.  Most of my e-mail servers require authentication to send e-mail and I am sure the entire industry is trending that way.
  • The ZyWall's date defaults to 1/1/2000. If you do not set the date/time, all of your firewall logs will be stamped with the incorrect date. Unfortunately, you can not set the date/time through the web interface. You must telnet to the device and change it under the maintenance menu.  The date/time setting should be in the web interface or better yet, get the time and date from the internet!
Summary
In summary, the ZyWall 10 is a serious Firewall. The new web interface on ZyNOS makes the setup a snap. You get a professional level firewall with stateful packet inspection without having to be a network specialist. If a NAT router isn’t good enough for you, try the ZyWall 10.
This article was republished by ZyXEL here
Google
Web HomeNetHelp
8 comments
ZyXel ZyWall 10 internet security gateway and router reviewed
ZyWall 10 by Al Otero - 9/26/2001 3:22:00 PM
Re: ZyWall 10 by Monty - 3/28/2002 2:48:00 PM
Zywall 10 (II) New? by Tim - 10/28/2002 2:08:00 PM
Re: Zywall 10 (II) New? by Greg - 11/8/2002 5:44:00 AM
Re: Zywall 10 (II) New? by Nick Till - 11/19/2002 1:11:00 PM
Re: Zywall 10 (II) New? by Thomas Lackey - 3/30/2003 4:29:00 PM
Posted by Thomas Lackey
3/30/2003 4:29:00 PM.
Re: Zywall 10 (II) New?
Depends on what you are doing.

The Zywall offers some more advanced features, but they are only useful if you need them.

One, it is a true SPI firewall, while the SMC and Linksys are not. Both those are a tiny little bit better than NAT only, by virtue of some fancy firmware, (Linksys claimed SPI for a while, but yanked it from current firmware as it did not work properly.) but they lack the hardware necessary to actually perform it.

Second would by Multi-NAT (worth looking up).

Third would be more virtual server options. However, at least the SMC I know would do enough for most environments.

Fourth, and important for businesses, is the content filtering. I personally wouldn't mind turning it on for home either.

Fifth, and actually probably the most important (heh) is its logging and alterting. Someone could port scan your SMC or Linksys all day and odds are it would never notice, and it certainly couldn't alert you. The Zywall would detect the scan (or attack) and alert you by e-mail immediately.
Re: Zywall 10 (II) New? by John - 11/17/2004 8:47:00 AM
Posted by John
11/17/2004 8:47:00 AM.
Re: Zywall 10 (II) New?
The Netgear FVS318 does do everything the Zywall 10 does plus some. It does have TRUE SPI among excellent email logging, DDOS for people who use dyndns.org , etc, it has all the features of Zywall. Check your products before you go bashing them. Linksys and SMC may suck but the Netgear has been just fine for some of the SOHO's our firm has consulted with on their firewalls. If your really a freak about security get a Cisco PIX, Netscreen or SonicWall
Re: Zywall 10 (II) New? by Cris Mooney - 3/4/2006 3:34:00 PM
Posted by Cris Mooney
3/4/2006 3:34:00 PM.
Re: Zywall 10 (II) New?
Multi-NAT & VOIP: I recently purchased a Netgear FVS338 and have found that it does not support Voice over IP (VOIP) - my SunRocket "Gizmo" VOIP box works in front of it, not behind it (packet sniffing showed the firewall is eating some SIP packets despite attempts to monkey with port forarding rules). I purchased the Netgear for Multi-NAT with Quality of Service so the VOIP would be reliable, but no go (10 hours or so into it). I don't have answers yet, but do beware of Netgear and VOIP (I am considering ipeya.com for a work PBX, and they recommened looking at ZyWall, so it may be better). A VOIP/NAT mildly useful read: "www.intertex.se/index2.asp?iMenuID=279&iItemID=223". Contact abuse at forus.com for a packet trace if you are bored.

Need some online coupons and merchant discounts? Check CouponClock.com!

No Poll Today
 
HomeNetHelp: the home computer networking and Internet connection sharing resource
201 users on-line
aprox 0 users today
9/3/2010 2:52:32 PM
(c)2001 Anomaly, Inc
Site Index